Privacy Policy
Disclaimer: The Company can modify this Policy unilaterally at any time, with notice as required under Applicable Law. Modification may be necessary, among other reasons, to maintain compliance with applicable laws and regulations (including the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and rules made thereunder) or to accommodate organizational changes within the Company. Please revisit this page regularly to stay informed of any changes. If you do not agree with any part of this Policy, please stop using our Platform immediately.
This Privacy Policy (“Privacy Policy” or “Policy”) governs use of the Service provided by Rivergo Automation Private Limited (“Company”, “We”, “Us”, “Our”), a “Data Fiduciary” as defined under the DPDP Act. This Privacy Policy is a legal agreement between the End-User (“You”, “Data Principal”) and the Company. It describes the privacy practices of the Company and its Affiliates. Your use of our Service constitutes your agreement to this Privacy Policy and provides the legal basis for our processing of your Personal Data.
The manner in which Your Information (including Personal Data and Sensitive Personal Data) is collected, retained, shared, stored, and processed by Us is addressed in this Policy. IF YOU DO NOT AGREE TO THIS PRIVACY POLICY, THEN YOU ARE PROHIBITED FROM USING OUR SERVICE.
This Privacy Policy forms part of our Terms of Service. See our End-User Agreement for additional terms governing your use of our Service generally. Capitalized terms used herein but not defined shall have the meanings assigned to them in our End-User Agreement or, where applicable, the DPDP Act.
1. Definitions (as used in this Policy, aligned with the DPDP Act)
- “Personal Data” means any data about an individual who is identifiable by or in relation to such data.
- “Data Principal” means the individual to whom the Personal Data relates, and where such individual is a child, includes their parent or lawful guardian.
- “Data Fiduciary” means the Company, which alone or with others determines the purpose and means of processing Personal Data.
- “Data Processor” means any entity that processes Personal Data on behalf of the Company.
- “Processing” means the entire cycle of operations performed on Personal Data, including collection, recording, storage, use, sharing, and erasure.
- “Consent Manager” means a person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform, where applicable to our Service.
- “Sensitive Personal Data” shall have the meaning given to it under our End-User Agreement and Applicable Law.
2. What personal information do we collect, and when?
2.1 Information obtained from End Users during registration
To avail the Service, you must register with us and pay the Service Subscription Fee within the timeline set out in the End User Agreement. As part of registration, you will provide information such as your name, email address, phone number, and any other information reasonably required to register you as an End User. Once this information is shared, the Company will contact you to collect basic information about your business. You become an End User only once all such procedures are completed.
2.2 Information obtained from End Users post-registration
Once registration is complete, you will be given access to the Dashboard, onto which you will upload files (which may contain large amounts of Sensitive Personal Data) stored on and accessed through the Dashboard. You acknowledge that such sharing, storage and streamlined access is the basis of your use of Febi for bookkeeping purposes, and you grant consent to Our access, storage and usage of such shared information for that purpose. We may also automatically collect your Usage Data, IP addresses (for tracking, determining region of origin, and login/security purposes), and use Tracking Technologies to track activity on our Service. Our Service may evolve over time and introduce features that collect new or different categories of information — where such collection is material, we will provide updated notice as required under the DPDP Act.
2.3 Information from visitors
Visitors who do not register as End Users may be tracked in the same manner described above; however, information required specifically for accessing the Service will not be collected from them.
2.4 Feedback Data and Other Data
- If you call our customer service, we may record information you provide, or record the call, for service delivery, quality and training purposes.
- Any feedback or comments you provide to us.
2.5 Device data
We collect data about devices used to access our Service (via Website or Application), including device IP address, unique device identifiers, advertising identifiers, serial numbers, device motion data, and mobile network data.
2.6 Data collected through cookies
Cookies are data collectors on websites that typically collect information such as language and preference settings, and time spent using the Service. This information is used to analyse how you interact with our Website. You may disable cookies through your browser, though this may prevent access to certain features of the Service.
2.7 Payment of Service Subscription Fee
We have engaged the payment gateway services of [PAYMENT GATEWAY NAME] for collection and settlement of the Service Subscription Fee. The privacy policy of [PAYMENT GATEWAY NAME], accessible at [INSERT LINK], governs the use, storage and processing of financial data by that gateway.
3. Notice and Consent (DPDP Act requirement)
Before or at the time of collecting your Personal Data, We will provide you with a clear and itemised notice, in plain language, describing:
- the Personal Data being collected;
- the specific purpose for which it is being collected and processed;
- the manner in which you may exercise your rights as a Data Principal; and
- the manner in which you may file a complaint with the Data Protection Board of India.
Your consent to processing of Personal Data is free, specific, informed, unconditional and unambiguous, given through clear affirmative action, and limited to the Personal Data necessary for the specified purpose. Where you are asked to consent to processing of Sensitive Personal Data, We will separately and clearly identify this. You have the right to withdraw your consent at any time, as easily as it was given, without affecting the lawfulness of processing carried out before such withdrawal. To withdraw consent, please refer to Section 8 (Your Rights) below.
Where required, We may make use of a registered Consent Manager to enable you to give, manage, review, and withdraw your consent.
4. How do we use your information?
- To pursue the Company’s legitimate business interests in connection with your use of the Service, including registration, responding to inquiries and requests, customer service, sending administrative information, and personalizing your experience with Febi.
- To better understand our users generally and improve the content and functionality of Febi.
- To communicate with you about the Service and, where you have consented, to send offers, newsletters, or marketing/promotional material relating to third-party products and services.
- To personalize or customize your experience, develop new features, and improve overall Service quality; and to notify you of changes to the Service.
- To operate our business, including providing the Service you requested; to provide support; to send notifications and reminders; and to protect the Service, including combating fraud.
- To fulfil the terms of our privacy policies, End User Agreement, or any other agreement We have with you.
- To resolve queries, follow up on your experience, verify your identity as an End User, provide support, and detect, prevent or address technical issues. Chat transmissions with support are encrypted; please do not share more Personal Data than necessary to resolve your issue. Session transcripts may be retained for this purpose.
- Feedback: Information volunteered in surveys or feedback may be combined with other customers’ responses to understand and improve the Service. Answering any survey is optional.
- Research: We may combine or publish aggregated, de-identified information such that no individual End-User can be identified, including sharing such aggregated findings with third parties for research, academic, marketing or promotional purposes.
All such processing is carried out either on the basis of your consent obtained in accordance with Section 3 above, or for “certain legitimate uses” recognised under the DPDP Act (for example, where you have voluntarily provided Personal Data for a specified purpose and have not indicated that you do not consent to its use).
5. Do we share your personal information with third parties?
We do not sell your personal information. We do not share it with third parties for their own marketing or advertising purposes unless you explicitly permit us to do so. Where We share Personal Data or Sensitive Personal Data with the following categories of recipients, We do so on the basis of your consent (where required) and subject to contractual safeguards requiring the recipient to process the data only for the specified purpose:
- Affiliates and Data Processors: engaged to help us operate the Service (e.g., website design, email communications, fraud detection and prevention, customer care, analytics), bound by confidentiality and purpose-limitation obligations, and processing data only on our instructions.
- Government/Legal Requests: shared with courts, law enforcement or government bodies where We have a good-faith belief this is required or permitted under Applicable Law, including for national security, or to respond to a court order, subpoena, search warrant, or law enforcement request.
- Protection of the Company/Others: shared where We believe it necessary to enforce our terms of service, protect the rights, property or safety of the Company, our Service, End Users, or others, and for fraud or credit-risk protection. This does not permit selling, renting or otherwise disclosing Personal Data for commercial purposes in violation of this Policy.
- Credit Bureaus: shared with credit bureaus, consumer reporting agencies and card associations, including in relation to late/missed payments, fraud, credit, or debt collection.
- Related Entities: shared with our Related Entities (except where prohibited under Applicable Law) to process transactions, maintain accounts, operate our business, facilitate login/registration, offer products/services, and detect or prevent fraud.
- Sale of Business: where We sell, merge, or transfer part of our business, your End User Data may be shared with the transferee; you will be given the option to stop receiving promotional information following any change of control.
- With Your Consent: for any other sharing not listed above, We will provide notice and an opportunity for you to choose.
6. Cross-Border Transfer of Personal Data
We may transfer your Personal Data outside India for processing and storage, in accordance with the DPDP Act. Such transfers will not be made to any country or territory that the Central Government of India has restricted by notification. Where Personal Data is transferred outside India, We will ensure that appropriate safeguards are applied so that your data continues to receive a standard of protection consistent with this Policy and Applicable Law.
7. How do we protect your personal information?
The Company limits access to Personal Data to authorized employees, associates, partners and officers, and holds third-party service providers to stringent privacy and confidentiality standards. We maintain physical, electronic and procedural safeguards, including:
- Use of specialized technology such as firewalls;
- Security and operability testing of products/services before deployment, and ongoing vulnerability scanning;
- Access, authentication and authorization controls across systems;
- Restrictions on use of external data devices on Company systems;
- Personnel training, and continual updates to security practices in light of new risks;
- Market-standard encryption to secure Personal Data and Sensitive Personal Data, including financial data.
No method of transmission over the internet or electronic storage is completely secure, and while We use commercially reasonable efforts to protect your data, We cannot guarantee absolute security.
8. Personal Data Breach Notification (DPDP Act requirement)
In the event of a Personal Data breach, the Company will, without undue delay, notify the Data Protection Board of India and each affected Data Principal in the form and manner prescribed under the DPDP Act and rules made thereunder, including a description of the nature, extent, and likely consequences of the breach, and the measures taken or proposed to mitigate the risk.
9. Your Rights as a Data Principal (DPDP Act)
Subject to Applicable Law, you have the right to:
- Right to Access Information: obtain a summary of the Personal Data We hold about you and the processing activities undertaken with respect to such data, including identities of any Data Processors and Data Fiduciaries with whom your data has been shared and the categories of data shared.
- Right to Correction and Erasure: request correction of inaccurate or misleading Personal Data, completion of incomplete data, updating of data, and erasure of Personal Data that is no longer necessary for the purpose for which it was collected (unless retention is required by law).
- Right to Grievance Redressal: raise a grievance with the Company in relation to the processing of your Personal Data, and receive a response within the timeline prescribed under Applicable Law.
- Right to Nominate: nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity.
- Right to Withdraw Consent: withdraw previously given consent at any time, as easily as it was given.
To exercise any of the above rights, please email [INSERT PRIVACY/RIGHTS EMAIL] with the relevant request clearly identified in the subject line (e.g., “REMOVE” for erasure requests). Please note you may not be able to continue using our Service after certain requests, such as deletion or withdrawal of consent, are processed — see Section 10 below.
If you are not satisfied with the Company’s response to your grievance, you have the right to file a complaint with the Data Protection Board of India, constituted under the DPDP Act.
10. Data Retention and Erasure
To the extent permitted by Applicable Law, We retain your End User Data only as long as necessary to fulfil the purpose for which it was collected, to operate our Service, or to comply with our legal obligations, whichever is longer, whether or not you remain a current End-User. You may request erasure of your End User Data by contacting us at [INSERT EMAIL]. Please note that Febi’s ability to provide the Service is dependent on your Personal Data being stored with Us; accordingly, upon erasure of your data, We may need to terminate or restrict your access to the Service.
11. Children’s Personal Data
Where Our Service is used by or on behalf of a child (as defined under the DPDP Act) or a person with disability who has a lawful guardian, We will process such Personal Data only with the verifiable consent of the parent or lawful guardian, obtained in a manner prescribed under Applicable Law. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children, and will not process children’s Personal Data in a manner likely to cause any detrimental effect on their well-being.
12. Grievance Redressal Officer
Should you have any grievances about the processing of your Personal Data or Sensitive Personal Data, you may contact our Grievance Redressal Officer:
Name: Rajat Kumar
Address: 45 Arjun Marg, DLF Phase I, Gurugram
Email: Info@febi.ai
All email messages sent to and from the Company may be monitored to ensure compliance with internal policies and to protect our business.
13. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, Service, or Applicable Law, including the DPDP Act and rules made thereunder. Where changes materially affect the manner in which your Personal Data is processed, We will provide notice as required under Applicable Law before such changes take effect.
14. Electronic Record
This document is an electronic record in terms of the Information Technology Act, 2000 and rules made thereunder, as applicable, and the amended provisions pertaining to electronic records in various statutes as amended by the Information Technology Act, 2000. This electronic record is generated by a computer system and does not require any physical or digital signature.